Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is reviewing AWS CloudTrail logs and notices a large number of `DescribeInstances` API calls from a single IAM user in a short period. The engineer suspects a credential compromise. What is the most effective way to automatically revoke the compromised credentials and notify the security team?

⚠ Common exam trap

Many exam-takers think CloudTrail or GuardDuty can directly take remediation actions, but they are detection-only services that require integration with compute services like Lambda for automated response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Amazon EventBridge rule that triggers an AWS Lambda function to revoke the keys and send an SNS notification.

It uses Amazon EventBridge to detect the anomalous DescribeInstances API calls (via CloudTrail as an event source), then triggers an AWS Lambda function to programmatically revoke the IAM user's access keys (using the `deactivate_access_key` or `delete_access_key` API), and sends an SNS notification to the security team. This provides an automated, near-real-time response to a suspected credential compromise without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail to automatically disable the IAM user's access keys.

    Why it's wrong here

    AWS CloudTrail is a read-only auditing service that records API activity across your account, but it provides no native remediation or automation capabilities. It cannot directly disable IAM access keys; any key deactivation would require external tooling such as an EventBridge rule invoking Lambda. Relying on CloudTrail alone leaves the compromised credentials active and only produces a log entry for post-incident analysis, so it is not a valid automated response mechanism.

  • ✓

    Create an Amazon EventBridge rule that triggers an AWS Lambda function to revoke the keys and send an SNS notification.

    Why this is correct

    Amazon EventBridge can match CloudTrail API events in near real-time using event patterns and then invoke an AWS Lambda function as a target. The Lambda function can call iam:UpdateAccessKey with Status=Inactive to revoke the compromised key(s), and it can also publish a message to an SNS topic to alert security personnel. This serverless pattern is a recommended, native AWS approach for automated incident response to suspicious IAM activity, making it the correct choice here.

  • ✗

    Create an AWS Config rule that checks for excessive API calls and revokes keys.

    Why it's wrong here

    AWS Config is designed for resource compliance and configuration history, not for real-time API call monitoring or volumetric threat detection. A Config rule can evaluate whether resources conform to desired policies and optionally run SSM Automation remediation, but it does not natively analyze CloudTrail logs for excessive API calls or trigger key revocation based on API behavior. Attempting to use Config for this purpose would require custom, inefficient workarounds and still would not provide the immediate, event-driven response needed for a credential compromise.

  • ✗

    Enable Amazon GuardDuty to automatically revoke compromised credentials.

    Why it's wrong here

    Amazon GuardDuty is an intelligent threat detection service that uses machine learning to identify suspicious activity, such as unusual API calls or credential usage, and generates findings. However, GuardDuty does not perform any automatic remediation actions—it only detects and alerts; you must build a separate response mechanism (e.g., EventBridge + Lambda) to act on those findings. Enabling GuardDuty alone will not disable compromised IAM keys, so this option is incorrect for an automated key-revocation requirement.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.